// engineering
Engagements.
Commercial work falls into four shapes. Every engagement starts with a scoping call, a written statement of work, and an NDA where appropriate. No tiered support, no offshored execution — you talk to the engineer doing the work.
[ AI-AUDIT ]
AI security assessment
Structured evaluation of an AI product's security posture — model, prompts, agent topology, tool boundaries, data handling. Output is a written report with severity-ranked findings and concrete remediation guidance.
↳ best fit: Companies shipping LLM products who need an outside read before launch, fundraising, or enterprise sales.
[ RED-TEAM ]
Adversarial red-team engagements
Time-boxed adversarial testing of a deployed AI system: jailbreaks, prompt injection, agent abuse, refusal-bypass, data exfiltration paths. Scoped to your threat model, not a generic checklist.
↳ best fit: Teams with an AI product in market or in late-stage build who want to know what an adversary would actually find.
[ INFRA ]
Secure AI infrastructure
Design and build of on-premise or air-gapped inference stacks for organizations that can't (or won't) send data to a hyperscaler. Covers model selection, hardware sizing, network isolation, and operational tooling.
↳ best fit: Healthcare, legal, defense-adjacent, and any team handling sensitive data who needs AI capability without the data-sharing tax.
[ ADVISORY ]
Technical advisory
Ongoing consultation for security or engineering leadership navigating AI risk — threat modeling, vendor evaluation, policy review, incident analysis. Retainer or per-engagement.
↳ best fit: CISOs, security leaders, and founders who want a knowledgeable second opinion in the room.
// process
How an engagement runs.
- 01
Scoping call
30–45 min, free. We discuss the system, the threat model, and what "good" looks like at the end.
- 02
Statement of work
Written scope, deliverables, timeline, and price. Fixed-fee or T&M. Mutual NDA.
- 03
Execution
Work happens on isolated lab hardware. Weekly progress notes. Critical findings escalated same-day.
- 04
Report + walkthrough
Written report (executive summary + technical detail), live walkthrough with your team, and follow-up retest of remediated findings included.
Start a conversation.
Reach out with a few sentences about what you're working on.
dev@aesirkode.com ↗